The short version
- We collect only what we need to run your account, your servers and your billing.
- We don't sell your information, and we don't use advertising or analytics trackers.
- Card details go straight to Stripe and PayPal details stay with PayPal. We never see your full card number.
- Your websites and the data of your visitors belong to you. We handle them only to host them.
- You can ask us to see, correct, export or delete your data at any time.
Who we are
Rabbitflare provides managed WordPress hosting on DigitalOcean through the website rabbitflare.com and the control panel at app.rabbitflare.com (together, the “Service”). Rabbitflare is operated by Rabbit Rank LLC, a company based in the United States (“Rabbitflare”, “we”, “us”). Payments for the Service are processed in the name of Rabbit Rank LLC.
For the personal information described in this policy, we are the data controller. This policy covers the Service, the emails we send and your conversations with our support. It does not cover the websites you host with us (see Your websites and visitors) or third-party websites, such as PayPal, that you may visit through the Service.
Information we collect
Information you give us
- Account details: your name, email address and password. We store your password only as a salted one-way scrypt hash, so we can't see or recover it.
- Servers and sites: the names, plans and regions you choose; site names and titles; the domain names you connect; the WordPress administrator username and email address for each site; and the cron jobs you set up.
- Support messages: anything you send us when you contact support.
Information created when you use the Service
- Sign-in and security data: for each signed-in session, a session identifier (stored hashed), the IP address and the browser user agent. We also briefly use IP addresses to limit repeated sign-up, sign-in and password-reset attempts.
- Server data: your servers' IP addresses and the WordPress administrator password we generate for each site, which we store encrypted (AES-256-GCM). We also collect resource metrics (CPU, memory, disk, load and bandwidth) from DigitalOcean's monitoring and the recent output of your cron jobs (the last 20 runs of each job).
- Activity log: a record of what happens to your servers and sites (for example “SSL certificate issued”), with the time and whether you, our systems or an administrator made the change.
- Files: when you use the File Manager, the files you open, edit or upload pass through our systems to and from your server. We don't keep copies of them.
- Technical data: like any website, the servers that deliver our pages process your IP address, the page requested and the time, to deliver them and protect against abuse.
Information from payment providers
- Stripe (cards, Apple Pay and Google Pay): you enter card details into a secure Stripe form on our pages; they go directly to Stripe and never reach our servers. Stripe gives us identifiers for your customer record, subscriptions and saved cards, and each saved card's brand, last four digits and expiry date so we can show them to you.
- PayPal: you approve payments on PayPal's website. PayPal gives us a subscription identifier, its status, and the email address of the PayPal account used.
- We keep the plan, price and status of each subscription, and invoice information from Stripe or PayPal to show your billing history.
Our homepage, rabbitflare.com, uses no analytics or third-party scripts. It sets one cookie of its own, to remember your cookie choices, and our hosting network sets one security cookie. Optional preferences are stored only with your consent. See our Cookie Policy for every cookie we use and how to change your choices.
How we use it
We use personal information only for the purposes below. Where the GDPR or UK GDPR applies, the legal basis for each is shown in brackets.
- To provide the Service: creating your account, building and running your servers and sites, issuing SSL certificates, backups, cron jobs, the File Manager, and support (performance of our contract with you).
- To take payments and keep billing records (contract, and our legal obligations for accounting and tax).
- To send service emails: confirming your email address, password resets, when a server is ready, payment problems and changes to your subscription (contract). We don't send marketing emails.
- To keep the Service secure: protecting accounts, preventing fraud and abuse, and investigating problems (our legitimate interest in a safe, reliable service).
- To fix and improve the Service using error logs and activity records (legitimate interests).
- To meet legal obligations, such as responding to lawful requests from authorities (legal obligation).
We don't use your information for advertising, we don't build marketing profiles, and we don't make automated decisions that have legal or similarly significant effects on you.
Who we share it with
We don't sell your personal information, and we don't share it for cross-context behavioral advertising. We share it only with the service providers who help us run the Service:
| Provider | What they do for us | Privacy information |
|---|---|---|
| DigitalOcean | Hosts our website, control panel and database, and runs your servers, backups, snapshots and monitoring in the datacenter you choose. | Privacy policy |
| Cloudflare | Delivers our website and control panel and protects them from attacks and bots, as part of DigitalOcean's hosting. | Privacy policy |
| Stripe | Processes card, Apple Pay and Google Pay payments, stores saved cards, and screens payments for fraud. | Privacy policy |
| PayPal | Processes PayPal payments and subscriptions. | Privacy statement |
| Resend | Delivers the emails we send you. Our emails contain no open or click tracking. | Privacy policy |
| Let's Encrypt | Issues free SSL certificates for your domains. | Privacy policy |
Stripe and PayPal also act as independent controllers for some of the information they collect, for example to meet financial regulations and prevent fraud, and their own privacy policies apply to that. Please note that SSL certificates are publicly logged: every domain name we request a certificate for appears in public Certificate Transparency logs, as it does with any certificate authority.
We may also disclose information if the law requires it, to protect the rights, property or safety of our customers, the public or Rabbitflare, or to a buyer or successor if our business is ever sold or reorganized, in which case this policy continues to apply.
Where your data is stored
Our control panel and its database are hosted by DigitalOcean in New York, in the United States. Your servers, and the websites on them, run in the DigitalOcean datacenter you choose: there are 11 to choose from in North America, Europe and Asia Pacific. Our other providers may process data in the United States and other countries.
If you are in the European Economic Area, the United Kingdom or Switzerland, this means your personal information is transferred outside your country. Where we do this, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum) included in our providers' data processing terms.
How long we keep it
- Account and server records: for as long as your account is open. When you ask us to delete your account, we delete or anonymize them within 30 days, except what we must keep by law.
- Billing records: kept as long as tax and accounting laws require, which is usually several years.
- Sign-in sessions: end after 30 days or when you sign out. Expired sessions are deleted within the hour.
- Password-reset and email-confirmation links: deleted once used or expired.
- Background tasks, including the details of emails queued for sending: deleted 14 days after they finish.
- Payment notification records from Stripe and PayPal: deleted after 90 days.
- Cron job output: only the 20 most recent runs of each job are kept.
- Your servers, sites, backups and snapshots: until you delete them. Destroying a server deletes it together with its sites, backups and snapshots. A server that is never paid for is removed after 48 hours.
Your websites and your visitors
The WordPress sites you host with Rabbitflare, and any personal information in them (such as your visitors' comments, orders or form entries), belong to you. For that information, you are the controller and we act as your processor: we store and process it only to host your sites and provide the Service, to keep it secure, to provide support you request, or where the law requires it. We never use it for our own purposes.
You are responsible for your sites' own privacy notices and for any consent your sites need, for example for cookies set by WordPress plugins. If you need a data processing agreement for your use of the Service, contact us.
Security
We protect your information with measures including:
- Encryption in transit (HTTPS) everywhere, and secure, HttpOnly session cookies.
- Passwords stored only as salted scrypt hashes, and WordPress administrator passwords encrypted at rest with AES-256-GCM.
- Card details handled only by Stripe, a PCI DSS Level 1 certified payment provider.
- A firewall, brute-force protection and automatic security updates on every server, and each site isolated under its own system user and database.
- Access to production systems limited to the people and automation that need it.
No system is perfectly secure. If we become aware of a breach that affects your personal information, we will notify you and the relevant authorities as the law requires.
Your rights
You can update your name, email address and password at any time in the control panel's Settings. For anything else, email [email protected] from the address on your account and tell us what you need. We don't charge for this, and we'll reply within 30 days.
If you are in the EEA, the UK or Switzerland
You have the right to access your personal information, correct it, have it deleted, restrict or object to how we use it, and receive it in a portable format. Where we rely on your consent, you can withdraw it at any time. You also have the right to complain to your local data protection authority, though we'd appreciate the chance to help first.
If you are in California or another US state with privacy laws
You have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, and to have it deleted. We don't sell or share personal information for targeted advertising, so there's nothing to opt out of, and we don't use sensitive personal information to infer characteristics about you. You may use an authorized agent to make a request, and we won't discriminate against you for exercising any of these rights.
Children
The Service is for businesses and adults. It isn't directed at children under 16, and we don't knowingly collect their personal information. If you believe a child has given us personal information, contact us and we'll delete it.
Changes to this policy
We may update this policy as the Service changes. We'll change the “Last updated” date above, and if a change is significant we'll email you before it takes effect.
Contact us
For questions about this policy or your personal information, email [email protected]. Rabbitflare is operated by Rabbit Rank LLC.